VendorsSonicWallemail_securityany version
Vulnerabilities

SonicWall Email Security - any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Published 2021-04-09 · Analyzed
9.8KEVEPSS 0.887
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Published 2021-12-14 · Analyzed
9.0KEVEPSS 1.000
CVE-2021-20022
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Published 2021-04-09 · Analyzed
7.5KEVEPSS 0.165
CVE-2021-3450
CA certificate check bypass with X509_V_FLAG_X509_STRICT
Published 2021-03-25 · Modified
7.4EPSS 0.183
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2023-0655
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses.
Published 2023-02-14 · Modified
5.3EPSS 0.007
CVE-2021-20023
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Published 2021-04-20 · Analyzed
4.9KEVEPSS 0.514
CVE-2026-3468
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
Published 2026-03-31 · Analyzed
4.8EPSS 0.003
CVE-2026-3470
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.
Published 2026-03-31 · Analyzed
3.8EPSS 0.004
CVE-2026-3469
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.
Published 2026-03-31 · Analyzed
2.7EPSS 0.005